ClamAV Multiple Heap Buffer Overflow Vulnerabilities (CVE-2014-9328)
Release date:
Updated on:
Affected Systems:
ClamAV <0.98.6-1. el7
Description:
Bugtraq id: 72372
CVE (CAN) ID: CVE-2014-9328
Clam AntiVirus is a Unix GPL AntiVirus tool kit, which is used by many email gateway products.
ClamAV has a heap buffer overflow vulnerability when processing the constructed upack package file. Attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
<* Source: Sebastian Andrzej Siewior
*>
Suggestion:
Vendor patch:
ClamAV
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://admin.fedoraproject.org/updates/clamav-0.98.6-1.el7
Completely open-source anti-virus software ClamAV
Install Comodo Antivirus in Linux
Build ClamAV in Linux
This article permanently updates the link address: